Privacy Policy

Privacy Policy (App)

As of June 26, 2026

1. General Information

Any use of data collected by the app or entered by you within the scope of using the app is based on the data use agreement entered into with you upon registering to use the app, for the purposes explained in the data use agreement and this Privacy Policy. You may revoke your data protection consent at any time with effect for the future. Consent can be revoked by sending an email to privacy@tuya.com.

The provision of your personal data in the app is generally neither legally nor contractually required. You are free to use the app. Nevertheless, providing the functions of this app requires the processing of your personal data.

Generated data linked to your app account (such as configuration and operating data, error logs, configuration settings, temperature curves, etc., collectively "System Data") will not be deleted, but will remain continuously available to you as long as the contract under the Terms of Use between you and us remains in effect.

You can delete the system data and your account data in the app at any time by deleting your app account.

The collection, transmission, storage, processing, and other use of personal data is hereinafter also collectively referred to as "processing."

2. Controller

The controller is Tuya GmbH, Peter-Müller-Straße 16/16a, 40468 Düsseldorf, Germany.

Tuya Customer Service Department: 1-844-672-5646 or service@tuya.com

Tuya Data Protection Office: privacy@tuya.com

3. Data Collection in the App

Upon registration, installation, and use of the app, data is processed:

  • Registration data: Email address, password (encrypted)
  • Device data: Device ID, model, serial number
  • Usage data: Settings (temperature, modes), schedules
  • Technical data: IP address, operating system, app version
  • Location data (optional): For automation (e.g., geofencing)
  • Cloud data: Control data processed via the Tuya IoT platform
The processing of this data is technically necessary to operate the app and to provide all its functions. The legal basis for this is Art. 6 (1) sentence 1 (b) GDPR.

Furthermore, personal data is processed on the basis of Art. 6 (1) sentence 1 (f) GDPR. This legal basis permits the processing of personal data within the scope of the "legitimate interests" of the controller. Our legitimate interest exists for the following purposes:

  • Provision and operation of software functionalities
  • Remote control and automation of connected products
  • Error analysis and system security
  • Improvement of product features
In the app, you have the option to unlock additional features. Once unlocked, data for these optional features will be transmitted. The legal basis for this is your consent pursuant to Art. 6 (1) sentence 1 (a) GDPR. You have the option to revoke the activation and stop data transmission within the app at any time.

4. Use of the Tuya Platform

The app uses Tuya's IoT platform for device communication. In doing so, data may be processed on servers outside the EU. The transfer is carried out on the basis of the data use agreement entered into with you upon registration for the app, in compliance with appropriate safeguards in accordance with the GDPR. You can view Tuya's privacy policy at:


If you have any questions, you can also contact privacy@tuya.com.

5. Cookies and Tracking

The app does not use traditional cookies, but employs comparable technologies for analytics and functionality. These include the following third-party in-app SDK services:

Google SDK

  • Third Party: Google LLC
  • Purpose of Use: Google may use various types of location information to make certain services and products more useful to you, depending on the product used and the settings selected. This location information includes:

    • GPS and other sensor data from your device
    • IP address
    • Activity across Google services, such as your searches or labeled places (e.g., your home or work address)
    • Information about things near your device, such as Wi-Fi access points, cell towers, and Bluetooth-enabled devices
  • Use Cases: To return the user's location information to the app, display the user's location on the map, and provide developers with corresponding services based on user location information.
Mapbox SDK

  • Third Party: Mapbox
  • Purpose of Use: To provide corresponding services, we offer issue tracking, troubleshooting, diagnostic services, and perform data statistics to ensure the normal operation of products and services.
  • Use Cases:

    • Location information: For example, the location of an event where an individual signed up to receive communication or interact with Mapbox.
    • Internet or other network/device activity: When you visit any Mapbox website, Mapbox automatically receives certain information such as: (a) browser and device type, (b) operating system, and (c) referring web pages including pages visited on such websites; as well as information such as IP address, data collected via strictly necessary and accepted website cookies / similar technologies. For information about cookies on Mapbox's website, settings, and how to change browser cookie settings, please visit the Mapbox website.
FCM SDK

  • Third Party: Google LLC
  • Purpose of Use: Push notifications to the device system's notification bar.
  • Use Cases: IP address (How it helps: Cloud Functions use IP addresses to run event handlers and HTTP functions based on user actions; Storage: Cloud Functions store IP addresses only temporarily to provide the service.) Firebase Cloud Messaging (Firebase Cloud Messaging uses Firebase installation IDs to determine which devices to send messages to.)
Twitter Login SDK

  • Third Party: Twitter Inc.
  • Purpose of Use: Login
  • Use Cases: Login
  • Collected Information: Device information: Device model, operating system, unique device identifier (refers to a string programmed into the device by the device manufacturer that can be used to uniquely identify the respective device), login IP address, network access method, type and status, network quality data, device accelerometer (gravity sensor).
  • Privacy Policy Link: https://x.com/de/privacy
Google Login SDK

  • Third Party: Google LLC
  • Purpose of Use: Login
  • Use Cases: Login
  • Collected Information: Device information: Device model, operating system, unique device identifier (refers to a string programmed into the device by the device manufacturer that can be used to uniquely identify the respective device), login IP address, network access method, type and status, network quality data, device accelerometer (gravity sensor).
Facebook Login SDK

  • Third Party: Meta Platforms, Inc.
  • Purpose of Use: Login
  • Use Cases: Login
  • Collected Information: Device information: Device model, operating system, unique device identifier (refers to a string programmed into the device by the device manufacturer that can be used to uniquely identify the respective device), login IP address, network access method, type and status, network quality data, device accelerometer (gravity sensor).
TUTK SDK

  • Third Party: IoT Intelligence (Shenzhen) Co., Ltd.
  • Purpose of Use: To implement the video preview function of IPC devices.
  • Use Case: When connecting to an IPC device to use the preview function.
  • Data Collection Details: Smart device information, IP address.
Shangyun P2P SDK

  • Third Party: Shenzhen Shangyun Internet Technology Co., Ltd.
  • Purpose of Use: To implement the video preview function of IPC devices.
  • Use Case: When connecting to an IPC device to use the preview function.
  • Shared Information: Camera device ID, network information (IP, current network type, and name).
  • Sharing Method: SDK local collection, background interface transfer.
  • Data Collection Details: No personal data is collected.
  • Official Website Link: http://www.cs2-network.com/
Yitong SDK

You can also view the list of in-app SDK services at:


If you have any questions, you can also contact privacy@tuya.com.

6. Third-Party Services

Third-party service providers acting as data processors for EU users are:

Amazon Web Services, Inc.

  • Place of Data Processing: EU
  • Scope of Processed Data: All data stored through the cloud: Cloud service; phone number and email address: SMS, emails.
  • Purpose of Data Processing: To enable cloud services via IaaS; data storage in data center instances for the data controller.
Nexmo Inc. (Vonage)

  • Place of Data Processing: EU
  • Scope of Processed Data: Phone number: SMS, phone calls.
  • Purpose of Data Processing: Providing verification codes via SMS for security checks during account login.
Microsoft Azure

  • Place of Data Processing: EU
  • Scope of Processed Data: App version, user ID.
  • Purpose of Data Processing: Notification of app versions for updates and feature enhancements sent to users; push and map services.
Hangzhou Tuya Information Technology Co., Ltd.

  • Place of Data Processing: China PR
  • Scope of Processed Data: Applicable user data in accordance with requirements to fulfill users' technical support requests or data requests.
  • Purpose of Data Processing: To enable the service provider's technical team to provide technical support, troubleshooting, and/or other requested services to app users. The scope of user data is strictly limited to the required data, and all employees who may have access to such data are strictly subject to access control systems and contractually bound to access data only on a need-to-know basis and keep all retrieved data confidential.
You can also view third-party service providers acting as data processors for EU users at:


If you have any questions, you can also contact privacy@tuya.com.

7. Revocation of Your Consent to Data Processing

Many data processing operations are only possible with your express consent. You can revoke consent that has already been granted at any time. An informal notification sent to us via email is sufficient for this purpose. The legality of the data processing carried out prior to the revocation remains unaffected by the revocation.

8. Right to Lodge a Complaint with the Competent Supervisory Authority

In the event of breaches of data protection law, the data subject has the right to lodge a complaint with the competent supervisory authority. The competent supervisory authority for data protection issues is the state data protection officer of the federal state in which our company is based. A list of data protection officers and their contact details can be found at the following link:


9. Right to Data Portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a standard, machine-readable format. If you request the direct transfer of the data to another controller, this will only be carried out to the extent technically feasible.

10. Access, Blocking, Deletion

Within the scope of the applicable statutory provisions, you have the right at any time to free information regarding your stored personal data, its origin and recipients, and the purpose of data processing, as well as, if applicable, a right to rectification, blocking, or erasure of this data. For this purpose, as well as for further questions regarding personal data, you can contact the controller named in Section 2 at any time.
Prepared by  T-Soft E-Commerce.